无法获取AWS EC2实例元数据ami-id,请求技术支持
问题:无法通过curl获取AWS EC2实例的ami-id元数据
问题描述
尝试使用curl命令获取AWS EC2实例元数据时,请求ami-id路径无输出,但请求元数据根目录能正常返回列表。已修改实例元数据配置,但问题依旧。
脚本内容
sysadm@ip-172-31-44-113:~/three-questions/query-script$ cat script.sh #!bin/bash TOKEN=`curl -X PUT \"http://169.254.169.254/latest/api/token\" -H \"X-aws-ec2-metadata-token-ttl-seconds: 21600\"` \ && curl -H \"X-aws-ec2-metadata-token: $TOKEN\" -v http://169.254.169.254/latest/meta-data/ curl -H \"X-aws-ec2-metadata-token: $TOKEN\" -v http://169.254.169.254/latest/meta-data/ami-id
执行脚本后的输出
sysadm@ip-172-31-44-113:~/three-questions/query-script$ sh script.sh % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 100 56 100 56 0 0 8032 0 --:--:-- --:--:-- --:--:-- 9333 * Trying 169.254.169.254:80... * Connected to 169.254.169.254 (169.254.169.254) port 80 (#0) > GET /latest/meta-data/ HTTP/1.1 > Host: 169.254.169.254 > User-Agent: curl/7.81.0 > Accept: */* > X-aws-ec2-metadata-token: > * Mark bundle as not supporting multiuse * HTTP 1.0, assume close after body < HTTP/1.0 200 OK < Accept-Ranges: bytes < Content-Length: 331 < Content-Type: text/plain < Date: Sun, 04 Dec 2022 07:23:08 GMT < Last-Modified: Sun, 04 Dec 2022 06:12:40 GMT < X-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600 < Connection: close < Server: EC2ws < ami-id ami-launch-index ami-manifest-path block-device-mapping/ events/ hostname identity-credentials/ instance-action instance-id instance-life-cycle instance-type local-hostname local-ipv4 mac managed-ssh-keys/ metrics/ network/ placement/ profile public-hostname public-ipv4 reservation-id security-groups services/ system * Closing connection 0 tags/* Trying 169.254.169.254:80... * Connected to 169.254.169.254 (169.254.169.254) port 80 (#0) > GET /latest/meta-data/ami-id HTTP/1.1 > Host: 169.254.169.254 > User-Agent: curl/7.81.0 > Accept: */* > X-aws-ec2-metadata-token: > * Mark bundle as not supporting multiuse * HTTP 1.0, assume close after body < HTTP/1.0 200 OK < Accept-Ranges: bytes < Content-Length: 21 < Content-Type: text/plain < Date: Sun, 04 Dec 2022 07:23:08 GMT < Last-Modified: Sun, 04 Dec 2022 06:12:39 GMT < X-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600 < Connection: close < Server: EC2ws < * Closing connection 0
已尝试的操作
aws ec2 modify-instance-metadata-options \ --instance-id i-023xxxxxxxxxxxxeef \ --http-tokens required \ --http-endpoint enabled \ --http-put-response-hop-limit 3 \ --instance-metadata-tags enabled
解决方案
1. 修正脚本中的语法错误
你的脚本存在两个关键语法问题:
- Shebang错误:
#!bin/bash应改为#!/bin/bash(缺少前置斜杠),否则脚本可能用非bash的shell执行,导致变量赋值异常。 - 多余的转义引号:curl命令中的
\"会被bash解析为字面引号,导致curl请求的URL和Header参数错误,无法正确获取token。去掉所有转义引号,改用正常引号。 - 推荐用
$()代替反引号`,可读性更好且避免嵌套问题。
修正后的脚本:
#!/bin/bash # 获取元数据token TOKEN=$(curl -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600") # 请求元数据根目录 curl -H "X-aws-ec2-metadata-token: $TOKEN" -v http://169.254.169.254/latest/meta-data/ # 请求ami-id curl -H "X-aws-ec2-metadata-token: $TOKEN" http://169.254.169.254/latest/meta-data/ami-id
2. 重启EC2实例使元数据配置生效
修改实例元数据选项(尤其是--http-tokens required)后,必须重启实例才能让配置生效。如果不重启,实例仍会允许无token的请求,但可能出现响应异常。
3. 排查curl输出问题
执行脚本时如果还是看不到ami-id输出,可以去掉-v选项(verbose模式可能会干扰正常输出),直接请求ami-id:
curl -H "X-aws-ec2-metadata-token: $TOKEN" http://169.254.169.254/latest/meta-data/ami-id
从你的执行输出可以看到,请求ami-id时服务器返回了Content-Length:21,说明已经返回了ami-id内容,只是因为脚本语法问题或verbose模式导致输出未显示。
内容的提问来源于stack exchange,提问作者Mayank Singh Rathore
相关产品推荐
相关产品推荐

